+8618758069661 [email protected]
Product Search Guide: space = AND, | = OR, ! = NOT

Industrial Switch VLANs: Access, Trunk, PVID, and 802.1Q Tagging

Got any Questions? Call us Today!

+8618758069661

Or leave us a message

Online Message

Industrial Switch VLANs: Access, Trunk, PVID, and 802.1Q Tagging

Views: 11Original by FCTELAuthor: FCTEL Technical Team

Virtual LANs divide one managed industrial switch into separate Layer 2 broadcast domains. The switch does not merely color cables: its forwarding database, broadcast flooding, and unknown-unicast flooding are scoped by VLAN. End devices normally use untagged access ports, while an uplink trunk carries several VLANs with IEEE 802.1Q tags.

Industrial switch access ports and tagged VLAN trunk
Access ports connect ordinary endpoints, while one tagged trunk transports control, operations, and video VLANs.

What VLAN separation actually controls

Broadcast and unknown-destination frames remain inside their VLAN. Control devices, cameras, and engineering stations can therefore share switching hardware without sharing one broadcast domain. Communication between VLANs requires a router, Layer 3 switch, or firewall, where policy can restrict the permitted direction and services.

VLANs are not a complete security system. Device authentication, management-plane protection, inter-VLAN access rules, and change control still require explicit design.

Access-port ingress and egress

Most PLCs, HMIs, and cameras send ordinary untagged Ethernet frames. When such a frame enters an access port, the switch assigns it to the port VLAN ID, or PVID. Internally, MAC learning and forwarding occur in that VLAN context. When the frame leaves an access port, the switch normally removes the 802.1Q tag before delivery to the endpoint.

A mismatch among PVID, allowed VLANs, and egress behavior can cause one-way traffic, incorrect DHCP service, or broadcasts entering the wrong zone. Troubleshooting must inspect both ingress classification and egress treatment.

PVID classification and 802.1Q tagging process
An untagged frame is classified by the ingress PVID; a trunk inserts a VID, and an access egress removes the tag.

How a trunk carries multiple VLANs

An 802.1Q trunk inserts a tag containing a VLAN identifier, allowing multiple broadcast domains to use one copper or fiber uplink. Both ends must allow the same VLANs and agree on treatment of untagged or native traffic. A trunk is not link aggregation: every VLAN still shares the capacity of the same physical link.

Plan the combined steady and burst load of all VLANs. Video bursts, engineering downloads, and control traffic can compete in the uplink queue even though their broadcast domains are separated. QoS and capacity planning remain necessary.

PVID and tagging are directional

PVID primarily classifies an untagged frame arriving at a port. Tagged or untagged membership often describes how frames leave. Engineers should separately answer three questions: which VLANs a port accepts, where an untagged ingress frame belongs, and whether each egress frame keeps or loses its tag.

A packet capture may not display an 802.1Q header when the mirror point sits after tag removal or when a capture adapter strips tags. Record the mirror location and compare the capture with VLAN tables, MAC tables, and port counters.

Industrial configuration and acceptance

Build a worksheet covering each device, switch port, VLAN, IP subnet, gateway, and permitted inter-zone flow. Keep management traffic separate from high-volume video, and disable unused ports or place them in an isolated VLAN. Lock the configuration version before commissioning.

Acceptance testing should verify same-VLAN communication, required inter-VLAN blocking or routing, broadcast containment, trunk restoration, and configuration persistence after restart. Test with real control, video, and maintenance load rather than relying on a simple ping. VLAN capabilities in FCTEL industrial switches vary by model and firmware; consult current documentation and validate the target topology.

Industrial network zones connected through controlled Layer 3 boundaries
Separate machine zones still need controlled routing, address planning, and firewall policy above the VLAN layer.